Skip to content

Errors / HTTP errors

403 Forbidden

The server understood the request and refuses to let you see this.

The page, or the file, is unavailable to whoever is blocked; sometimes only some visitors.

Seeing it on someone else’s site?

  • The site is deliberately blocking this address or this visitor: not a login problem (that would be 401).
  • A VPN, a shared network or an unusual browser can trip a site's firewall; try without the VPN or from another network.
  • If it names Cloudflare or says Error 1020, the site's security rules blocked you; only the site can change that.

Why it happens, if it is your site

  • A firewall or bot protection (Cloudflare, a WAF, a security plugin) blocking the request by country, IP, user agent or pattern.
  • File permissions on the server: the web server's user cannot read the file or folder.
  • A folder with no index file where directory listing is off.
  • An .htaccess or server rule denying access, often left by a security plugin or a migration.
  • An API key restricted to other domains, or a signed URL that expired.

How to fix it

  1. Read the 403 page itself: a firewall's page names the firewall and often the rule or a ray ID.
  2. Check the file's permissions and owner (644 for files and 755 for folders is the usual start) and that the folder has an index file.
  3. Look for deny rules in .htaccess or the server config, and in a security plugin's settings.
  4. For an API, check the key's allowed referrers include this site.

Whose problem it is

Either the site's own code or a third party's, depending on where it comes from.

Does your site have it?

Free, no account. We open your page and four more in a clean Chrome and list every error like this one, with the page and the click that caused it. How the free page check works.

Check only sites you run or have permission to check.

Often seen with